<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Require serial number match? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511205#M3062</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229831"&gt;@AProwant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately I don't have personal experiance (hope one day to have the same in our environment), but I believe you need the following:&lt;/P&gt;
&lt;P&gt;- You need Group Mapping with enabled "Fetch list of managed devices". This will tell the firewall to pull the serial number of AD computers over LDAP - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-server-profiles-ldap" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-server-profiles-ldap&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Create HIP object that as "Managed" set you "yes under General Tab -&amp;gt; Host Info&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you enable fetching device list in group mapping you should be able to see the list of retrieved devices with:&lt;/P&gt;
&lt;PRE class="_3GnarIQX9tD_qsgXkfSDz1"&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;&amp;gt; show user ldap-device-serialno all&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;If you don't see it either:&lt;/P&gt;
&lt;P&gt;- the service account you use for the LDAP doesn't have enough permissions&lt;/P&gt;
&lt;P&gt;- The serial number is not set as attribute for the computer objects in the AD - &lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/n1pe2p/global_protect_hip_check_machine_account_exists/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/n1pe2p/global_protect_hip_check_machine_account_exists/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 10:01:59 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2022-08-08T10:01:59Z</dc:date>
    <item>
      <title>Require serial number match?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511165#M3057</link>
      <description>&lt;P&gt;We are running&amp;nbsp;&lt;SPAN&gt;10.2.2 w/ GP 6.0.3 and I am unable to figure out how to have my serial number (discovered via HIP) be required to match what is in AD. Could someone please show me which way to go? Support and my sales engineer have been unable to assist.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 04:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511165#M3057</guid>
      <dc:creator>AProwant</dc:creator>
      <dc:date>2022-08-07T04:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Require serial number match?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511205#M3062</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229831"&gt;@AProwant&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately I don't have personal experiance (hope one day to have the same in our environment), but I believe you need the following:&lt;/P&gt;
&lt;P&gt;- You need Group Mapping with enabled "Fetch list of managed devices". This will tell the firewall to pull the serial number of AD computers over LDAP - &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-server-profiles-ldap" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-server-profiles-ldap&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Create HIP object that as "Managed" set you "yes under General Tab -&amp;gt; Host Info&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you enable fetching device list in group mapping you should be able to see the list of retrieved devices with:&lt;/P&gt;
&lt;PRE class="_3GnarIQX9tD_qsgXkfSDz1"&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;&amp;gt; show user ldap-device-serialno all&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;If you don't see it either:&lt;/P&gt;
&lt;P&gt;- the service account you use for the LDAP doesn't have enough permissions&lt;/P&gt;
&lt;P&gt;- The serial number is not set as attribute for the computer objects in the AD - &lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/n1pe2p/global_protect_hip_check_machine_account_exists/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/n1pe2p/global_protect_hip_check_machine_account_exists/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 10:01:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511205#M3062</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-08T10:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Require serial number match?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511284#M3067</link>
      <description>&lt;P&gt;Thank you so much. That worked perfectly!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 02:09:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/511284#M3067</guid>
      <dc:creator>AProwant</dc:creator>
      <dc:date>2022-08-09T02:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Require serial number match?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/596984#M5778</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm currently experiencing the same issue.&lt;/P&gt;
&lt;P&gt;We currently have a working LDAP connection to MS AD that is used for user group identification on GP HIP and works without issues.&lt;/P&gt;
&lt;P&gt;We are trying to identify machines through Serial Number for that purpose we have:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;On Device &amp;gt; User Identification &amp;gt; Group mapping settings &amp;gt; Fetch list of managed devices: YES&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;On Network &amp;gt; GlobalProtect &amp;gt; Portal &amp;gt; Agent (new) &amp;gt; Config Selection Criteria &amp;gt; Device Checks &amp;gt; Serial Number Check &amp;gt; Machine account exists with device serial number: YES&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;On Network &amp;gt; GlobalProtect &amp;gt; Portal &amp;gt; Agent (new) &amp;gt; HIP Data collection &amp;gt; Collect HIP Data: YES&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;On Objects &amp;gt; GlobalProtect &amp;gt; HIP Object (new) &amp;gt; host info &amp;gt; HIP Managed: YES&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On MS AD we have create a user group with the name and cn matching the serial number of the test pc&lt;BR /&gt;And we have added this new group into&amp;nbsp;&lt;SPAN&gt;Group mapping settings &amp;gt; Group include list.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unfortunately we keep on been unable to match the serial numbers because we are not receiving them from LDAP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show user ldap-device-serialno all&lt;/P&gt;
&lt;P&gt;ID|SerialNumber|Manged_by_AD|LastUpdateTime&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please can you let me know the MS AD&amp;nbsp; &amp;gt; LDAP side of the config that you did for this to work? And if anything else was done in the firewall side?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 13:51:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/require-serial-number-match/m-p/596984#M5778</guid>
      <dc:creator>IBisonni</dc:creator>
      <dc:date>2024-09-05T13:51:12Z</dc:date>
    </item>
  </channel>
</rss>

